CVE-2018-19907

CVSS v3.0 8.8 (High)
88% Progress
CVSS v2.0 6.5 (Medium)
65% Progress
EPSS 0.20 % (57th)
0.20% Progress
Affected Products 1
Advisories 1

A Server-Side Template Injection issue was discovered in Crafter CMS 3.0.18. Attackers with developer privileges may execute OS commands by Creating/Editing a template file (.ftl filetype) that triggers a call to freemarker.template.utility.Execute in the FreeMarker library during rendering of a web page.

Weaknesses
CWE-78
Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')
CVE Status
PUBLISHED
CNA
MITRE
Published Date
2018-12-06 07:29:00
(5 years ago)
Updated Date
2023-11-07 02:55:45
(10 months ago)

Affected Products

Loading...
Loading...
Loading...

Configuration #1

    CPE23 From Up To
  Craftercms Crafter Cms 3.0.18 and prior versions cpe:2.3:a:craftercms:crafter_cms <= 3.0.18
Loading...
Loading...
Loading...
Loading...
Loading...
Loading...
Loading...